Document version: vNPHI-1.0 · Effective date: 2026-07-29 · Last updated: 2026-08-17
This No-PHI & Confidentiality Policy (this "Policy") sets the rules for what you may and may not put into the Service. It explains why Sorxi does not accept Protected Health Information (PHI) or other confidential material at launch, how Sorxi enforces that rule, and what to do if confidential information enters the Service by accident.
This Policy applies to every User of the Service. It also binds Experts by reference: an Expert is subject to these same input rules and confidentiality obligations when using the Service and when handling any material provided through Get Backup.
This Policy is part of, and incorporated into, the Terms of Use. It works alongside the Privacy Policy and the Acceptable Use section of the Terms of Use. Where this Policy and another document address the same subject, read them together. Capitalized terms have the meanings given in the shared glossary.
You must not input, upload, paste, type, or otherwise transmit through the Service any of the following:
This is a default rule, not a preference. The Service is not configured at launch to receive, process, or store any of the material listed above. Do not attempt to work around the rule by disguising, abbreviating, or partially masking identifiers.
The only exception is where Sorxi has expressly agreed in writing, under a signed Business Associate Agreement (BAA) or Data Processing Agreement (DPA) that covers the specific data and use. No such agreement is in effect at launch. Until Sorxi tells you in writing that a covered pathway is active for your Organization, the no-PHI rule applies without exception.
Sorxi is designed to help without any patient-identifiable input. Describe situations in general, de-identified terms. Speak about the type of unit, the type of situation, and the process question you are working through. You do not need to identify a patient, a colleague, or an event to get useful Output.
Sorxi does not collect or store PHI at launch. Sorxi is designed at launch not to receive, process, or store PHI, and it does not offer a HIPAA-covered PHI workflow. Sorxi will handle PHI only under a written covered-data arrangement, including a signed Business Associate Agreement (BAA), for an Organization. The Service is not HIPAA-compliant at launch, and you must not use it as a system of record for any patient information. Handling PHI safely and lawfully requires legal agreements, security controls, and insurance that are not in place yet. The controls that would be required before any PHI pathway could open are listed in Section 6.
This Policy is not a Business Associate Agreement. Nothing in it creates a BAA or makes Sorxi a business associate. Sorxi will act as a business associate only under a separately signed BAA covering the specific data and use.
Keeping PHI and confidential material out of the Service protects you, your patients, your colleagues, and your Organization. It also keeps Sorxi honest about what the Service is: an educational AI-safety Workbench that provides education and process guidance, not a clinical or record-keeping system. For the full scope-of-service boundaries, see the disclaimers in the Terms of Use.
The no-PHI rule rests on you. You must not enter, upload, paste, or otherwise transmit PHI or confidential material into the Service. Keeping it out is your responsibility, and entering it breaches this Policy and the Terms of Use (see Section 7 for consequences).
Sorxi is built so that using it does not create a hidden record about a patient, an event, or a mistake.
This design means that debriefing an AI moment in the Service does not produce a document that could be pulled as a record of a specific patient, incident, or fault.
Sorxi may, in the future, enable a PHI-handling pathway for a specific Organization. If it does, that pathway will not turn on until the required controls are in place. Those controls include:
None of this is active at launch. A PHI pathway becomes available to you only when Sorxi tells your Organization in writing that it is active and under what terms. Until then, treat the no-PHI rule as absolute.
Entering PHI or other prohibited material violates this Policy, the Acceptable Use section of the Terms of Use, and the Terms of Use. Depending on the circumstances, Sorxi may warn you, restrict or suspend your access, disable an upload feature, or terminate your account, consistent with the Terms of Use. Sorxi may also purge affected content as described in Section 8. You remain responsible for your own compliance with HIPAA, your Organization's policies, and applicable law when you use the Service.
If you believe you have entered PHI or other confidential material into the Service by accident, report it promptly so it can be purged. Email help@sorxi.com and describe, in general terms and without repeating the sensitive content, what happened and where in the Service it occurred. Sorxi will locate and purge the affected content within 30 days. Prompt reporting helps limit exposure and supports Sorxi's controls under this Policy.
Questions about this document: help@sorxi.com